Devices and trusted sessions

Register application devices, manage push destinations, establish bounded trust, and revoke device-backed access from one explicit identity boundary.

Supported approaches

Device registration and inventory

available

Attach an installation to a user and application without conflating account clients with peer-to-peer pairing.

Packages

@playstack/devices

Frameworks and integrations

Push destinations

available

Rotate encrypted push credentials and resolve valid delivery targets without exposing provider tokens to callers.

Trusted-device sessions

available

Grant explicitly bounded device trust for MFA policy and revoke the device, its sessions, and push tokens atomically.

Frameworks and integrations

framework

Next.js

Compose Playstack server contracts, React bindings, SSR handoff, and route adapters at the Next.js application edge.

framework

NestJS

Connect portable Playstack capabilities to dependency injection, guards, decorators, request context, workers, and lifecycle hooks.

integration

Prisma

Persist Playstack capabilities through explicit application-owned Prisma clients, transactions, and managed schema fragments.

Package reference

@playstack/devices

Registered devices are application clients

A registered device represents an installation signed into an application. It gives authentication, MFA, and notifications a shared device identity without pulling peer discovery or transport into those packages. Device-to-device trust is a separate pairing capability.

Register and resolve from the server

The application owns persistence and request identity. Playstack owns lifecycle rules, credential protection, and the events other capabilities consume.

ts
import { createDevices } from '@playstack/devices'

export const devices = createDevices({
  persistence,
  cipher,
  events,
  clock,
})

const device = await devices.registerDevice({
  userId: session.userId,
  appId: 'dashboard',
  installationId: input.installationId,
  platform: input.platform,
  name: input.name,
})

await devices.registerPushToken({
  userId: session.userId,
  deviceId: device.id,
  provider: 'apns',
  token: input.pushToken,
})

Notification workers ask the device service for current targets at send time. A token invalidated after enqueue therefore cannot receive a later push.

Revoke the boundary, not one symptom

Revocation removes the active device, invalidates its push destinations, and emits the event authentication uses to revoke device-backed sessions. Trust has an absolute expiration and never becomes permanent merely because a device remains active.

Go

Playstack Pro tag
OriginsPricingBlogNewsletterChangelogStatusRoadmap
ContributorsCommunityIn Use ShowcaseCase StudiesPartnersSponsors
FAQsSupportContact

© 2026 Playstack. All rights reserved.

With OSS
Terms of ServicePrivacy PolicyCookie PolicyImprint

By

Commune Software